Vulnerability Details CVE-2012-6565
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.7%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2012-6565
-
cpe:2.3:a:vanderbilt:redcap:-
-
cpe:2.3:a:vanderbilt:redcap:4.14.0
-
cpe:2.3:a:vanderbilt:redcap:4.14.1
-
cpe:2.3:a:vanderbilt:redcap:4.14.2